CCI-003051
CCI-003051 Definition
Develop security and privacy plans for the system that explicitly defines the authorization boundary for the system.
Status | |
Type | CheckType.policy |
Master Assessment Datasheet
Implementation Guidance
The organization being inspected/assessed explicitly defines within the security plan the authorization boundary for the system.
Validation Procedures
The organization conducting the inspection/assessment obtains and examines the security plan to ensure the organization being inspected/assessed explicitly defines within the security plan the authorization boundary for the system.
Compelling Evidence
1.) Clearly defined system authorization boundary. 2.) Network diagram that accurately portrays the authorization boundary. 3.) Written description of the system authorization boundary in the authorization to operate (ATO) document matches the architecture and authorization boundary in the network diagram.